Effective October 1, Google announced that its Open Source Software Vulnerability Rewards Program will be suspended until sometime in 2027. The company cited a sharp increase in submissions generated by artificial-intelligence tools as the primary cause. By halting the program, Google hopes to reassess its processes and address the quality concerns raised by the influx.
The rewards program traditionally paid security researchers for identifying flaws in the open-source components that Google maintains. Earlier coverage by TechCrunch warned that low-quality AI-generated reports could undermine the effectiveness of such initiatives. Those warnings now appear to have materialized, prompting the company to take the unprecedented step of pausing the entire open-source bounty track.
Google communicated the suspension through posts on its X account and the program’s website, stating that the pause would begin on October 1 and that an update would be issued in the first quarter of 2027. The messaging emphasized that the decision was driven by the volume of automated reports rather than a strategic shift in the company’s security priorities.
According to reporting by Tom’s Hardware, Google engineers and the maintainers of its open-source projects found themselves swamped by submissions that were either invalid or contained hallucinated content. The surge in low-quality entries strained internal review processes and reduced the overall efficiency of the vulnerability triage pipeline, leading to the temporary shutdown.
In a formal statement, Google explained, “This pause is due to a significant rise in automated submissions, the vast majority of which are not valid.” The quotation underscores the company’s assessment that the bulk of recent reports lack substantive merit, prompting a reevaluation of how AI-generated findings are handled within the program.
Researchers who were previously participating in the open-source track are advised to explore Google’s other bounty offerings, which continue to operate without interruption. By redirecting effort toward those programs, security experts can still contribute to the company’s defensive posture while the open-source initiative undergoes review and potential redesign.